Back to the news overview

Data protection for online bookings for course providers

Data protection for course providers in Germany, Austria and Switzerland: clear forms, secure access, AVV and deletion periods for online bookings.

Anyone who offers courses and accepts registrations online processes personal data: names, email addresses, bookings and often payment information. Whether a language school, academy or company with internal training – data protection is therefore part of the normal booking process.

The task can be approached pragmatically. What is crucial is understandable information, economical forms, clear access rights and comprehensible processes. This article shows what course providers in Germany, Austria and Switzerland should pay attention to and how a booking system can support implementation.

Key points at a glance

  • Only collect data that you need for a clearly defined purpose.
  • Children's health claims and data require special attention.
  • A data protection-conscious booking system supports your work; You remain responsible for your processes.
  • Regulate order processing, access rights, retention and deletion.
  • For cloud services, also check the service providers involved and possible data transfers abroad.

What rules apply in the DACH region?

The basic goals are similar: personal data should be processed for a specific purpose, transparently, economically and securely. The EU General Data Protection Regulation and the Swiss Data Protection Act remain independent sets of regulations.

Germany and Austria

For course providers in Germany and Austria, the General Data Protection Regulation (GDPR) is central. National rules also apply, including Germany's Federal Data Protection Act and Austria's Data Protection Act.

Fulfillment of the contract may be the appropriate legal basis for the data required for booking. However, this does not mean that any additional use is automatically permitted. Newsletters, photos or specially protected data must be considered separately.

Switzerland and cross-border offers

The revised Data Protection Act (DSG) has been in force in Switzerland since September 1, 2023. Here too, appropriate security measures, understandable information and controlled processing of data are important.

For cross-border offers, the GDPR may also be relevant. Among other things, your location and the orientation of your offer are crucial. A Swiss provider can also fall under this if it specifically targets people in the EU. The nationality of a participating person alone does not answer this question.

An example from everyday booking practice

Imagine the following situation: In the registration form, an educational institute asks not only for your name, email address and course choice, but also for allergies for catering and emergency contacts for children's courses. A shared Excel list is then sent to all course instructors.

The problem arises during distribution: not every person needs all the information. A course leader may need the attendance list, but not billing details. Health information should only be accessible to those who actually need it for the specified purpose.

This illustrative example shows why data protection is more than a form notice. Data collection, transfer, access and deletion must fit together.

Where do risks arise when booking online?

Too many fields with no clear purpose

Registration forms often grow with new organizational wishes. Therefore, check each field: Why do we need this information? Do we really need to record them for every booking? A field without a comprehensible purpose should be omitted. Even a voluntary information needs a permissible purpose.

  • External course providers: A date of birth may be required for an age-dependent offering. An address may be needed, for example, for a legally required invoice or postal delivery.
  • Internal training: Department, role and evidence of competence may be important for organization. Define who needs to see this information for their work.
  • Children's courses: Limit information about children and contact persons to what is necessary for the particular course and supervision.

Children's health information and data

Allergies or physical limitations can be health data. Additional requirements apply to such information; An ordinary booking legal basis alone is not automatically sufficient under the GDPR.

Children’s data also deserves special care. However, they do not belong to the special data categories of the GDPR just because of their age. For each piece of information, consider who needs it, how it will be protected, and when it can be deleted.

Payment details, exam results and personal support notes should also only be accessible to appropriate people. A common list with all the information is often too broad for this.

Access rights too broad

Shared passwords, non-deactivated access for former employees and participant lists sent out in an uncontrolled manner make data protection more difficult. Roles help make data accessible by task.

  • Course instructors receive the information necessary to carry out the course.
  • Accounting receives access to the required invoice and payment data.
  • HR managers see required training certificates without automatically receiving all communication history.

Check permissions regularly and adjust them when tasks change or leave.

Cloud services and data transfers abroad

Check where your booking system processes data and which other service providers are involved. This may include, for example, payment or communication services. The location of the provider alone does not describe the entire data flow.

For overseas transfers, additional requirements may apply depending on applicable law. An appropriate level of data protection or suitable guarantees can be crucial. Data storage in Switzerland or the EU does not replace checking the services actually used.

Your checklist for data protection-conscious booking processes

  1. Provide clear information: Explain what data you collect, what you use it for, who receives it and the criteria for retaining it. The information should be easy to find before booking.
  2. Regulate data processing: If a service provider processes data on your behalf, the requirements for that processing must be set out in a contract. The data processing agreement (DPA) governs this relationship; it does not replace an assessment of whether your own processing is lawful.
  3. Review forms: Document the purpose of each field. Remove unnecessary information and assess health information or children's data with particular care.
  4. Define roles: Provide individual access accounts and restrict permissions to each person's task. Also define who may export or share data.
  5. Plan retention and deletion: Distinguish between invoice records, participant data and additional information needed only briefly. Define who checks the deadlines and carries out deletion.
  6. Implement technical and organizational measures: These include strong passwords, two-factor authentication, auditable access and backups with tested restoration. Avoid uncontrolled exports to personal devices.

Storing doesn’t mean storing everything for the same amount of time

Statutory retention periods apply to invoices and business records. In Germany, invoices must generally be retained for eight years. Austria generally has a seven-year retention requirement for the relevant accounting documents; in Switzerland, the general period for business books and accounting records is ten years. Different or longer periods may apply depending on the document and particular circumstances.

These requirements are no reason to keep all additional information for just as long. In the case of allergy information or emergency contacts, it must be checked whether the purpose no longer applies after the course. For participant data, it should also be clear when they are still needed and when they can be deleted.

Common mistakes in everyday life

  • “A cookie banner is enough.” A banner does not resolve questions about booking data, data processing agreements, permissions and deletion.
  • “The tool is compliant, so our process is automatically correct.” Software can help. Your forms, settings and internal processes remain decisive.
  • “Every booking requires consent.” Performance of a contract is often a suitable basis for necessary booking data. Additional purposes must be assessed separately.
  • “Data protection only concerns large organizations.” Small schools and academies also process personal data and must design their processes accordingly.

How edoobox supports your implementation

A central booking system can help to manage participant data, bookings, payments and communication in an orderly manner. In edoobox, roles and automated processes support the organization. Which information you request and which people are allowed to access it must match your offer.

edoobox's primary platform hosting is located in Zurich. Individual processors may process data abroad. Current information about data processing and agreements is available on the Data protection and compliance at edoobox page and in the privacy policy.

The technical basis does not release course providers from their responsibility. However, it makes it easier to organize responsibilities, access and booking processes in a structured manner.

Implement data protection step by step

Start with the processes you use every day: registration form, participant list, invoicing and email communication. Check the required data, access and retention. This turns an abstract topic into a manageable series of concrete tasks.

Try edoobox with no obligation: Test the online booking system for ten days and see how you can organize course bookings centrally with data protection in mind. Try it free now.

Sources and further information

Note: This article provides general information and is not a substitute for individual legal advice. For complex data protection questions, we recommend consulting a specialist.

Frequently asked questions about data protection when booking online

Do we need consent for every booking?

According to the GDPR, fulfillment of the contract can be the appropriate legal basis for data that is required for booking processing. Additional purposes such as newsletter marketing or certain tracking procedures must be examined separately. Additional requirements apply to health data.

Can we pass on participant lists to course instructors?

If the transfer is necessary and permitted for the course implementation, course instructors should only receive the information required for this purpose. Appropriate role access in the system can avoid uncontrolled email attachments. Health and billing information is not automatically included in every participant list.

When do we need an AVV?

If a service provider processes booking data on your behalf, the requirements for order processing or order processing must be regulated contractually. In addition, it remains necessary to check whether you are allowed to process the respective data for your purpose.

What applies to photos and videos in the course?

Before recording and publishing, clarify the purpose and legal basis. Voluntary, informed and purpose-related consent is usually the appropriate option for course and advertising photos. In the case of minors, the requirements for parental consent and the rights of the children must be taken into account.

Is a booking system that advertises GDPR compliance enough?

No. A suitable system supports your implementation. Whether the booking process complies with data protection also depends on your forms, purposes, access rights, agreements and deletion processes.

How long can we keep participant data?

This depends on the purpose and legal retention requirements. Differentiate invoice documents from organizational information and sensitive additional information. Set appropriate deadlines and delete data as soon as it is no longer needed and there is no obligation to retain it.

When does a legal examination make sense?

In complex constellations, such as a lot of health data, international data flows or extensive participant bases, a technical review makes sense. Clear documentation of your forms, service providers and access rules makes this check easier.

edoobox

Choose language